"" 검색 결과: 20개의 아이템
- How an Integrated Risk Management Approach to Security Increases Operational Resilience
Any organization managing cybersecurity risks has a daunting challenge. Security issues are identified and published online daily, mitigations may not arrive for weeks, and threats can originate across international borders. Narrowly focused best practices can become liabilities overnight. Conscientious and inflexible security practices may mitigate the risk of theft or intrusions but may come at the cost of efficiency and responsiveness. Risks can be invisible right up until they are a problem, and even trusted and seemingly secure supply chains can be disrupted or compromised. The lines that define safe operations are constantly shifting, as even existing technologies require fresh security assessments. It isn’t enough to make a one-time risk analysis of possible threats when integrating new practices or assets. We recommend organizations routinely determine the scope and business implications of cyber-attacks. In addition, being able to quantify and categorize risk can make the development of a risk management culture a concrete exercise with metrics and clearly defined goals. Establishing how each process and practice manages risk and increases operational resilience is easier with an integrated risk management approach to security. Leaders in integrated risk management have been expanding their abilities for mitigating risk with new tools that allow for coordinated security processes. See how to protect your organization with robust risk defenses by reading our report, “The State of Integrated Risk Management.” All Risk is Connected and Your Security Approach Should Be Too In the physical world, a strong perimeter defense can mitigate losses while still allowing businesses to operate within protected perimeters of a facility. However, cybersecurity perimeter defenses have long been problematic due to the very nature of digital risks and threats. When everything relies on the impregnability of a firewall or the secrecy of a password, everything is at risk if a firewall is breached, or a password is compromised. When the global COVID-19 pandemic led to workplace shutdowns, the opportunities for cyberattacks skyrocketed. Organizations that did not have an integrated security approach to cyberthreats were more vulnerable to attacks when their workforce was distributed across a spectrum of network security settings. When a flood of remote workers began accessing sensitive assets through home networks, many organizations relied on VPNs to allow personnel to tunnel into protected organization networks. Unfortunately, this adds as many points of security weaknesses as there are personnel remotely accessing the organization’s network. For example, the Colonial Pipeline ransomware attack used virtual private network login credentials to hold the Colonial Pipeline Company’s operations hostage. A single point of failure led to disruptions in mission critical operations. Reinforced Defenses against Disruption The concept of defense in depth has been around for decades and adds layers of protection wherever possible and practical. An integrated risk management approach to security builds on that concept by connecting processes and data from other risk functions since e every part of an operation is a possible security concern or source of risk. The key to designing and maintaining an integrated risk management approach to security is to make sure the entire process is aligned with operational resilience. The ability to remain in operation despite disruptions should be the primary motivating force behind your security approach. 1 in 5 of respondents in the RSA Digital Risk 2020 survey stated they are prioritizing the alignment of business resiliency and enterprise risk management approaches in the next two years. With an integrated risk management approach to security, different areas of an organization can manage their risk in a way that strengthens overall operational resilience. The efforts of IT and security weave together with regulatory and corporate compliance, third-party management, and other stakeholders to create a reinforced risk management program. Granular Risk and Response We recommend organizations compile a complete picture of technology and digital security related risks and understand their financial impacts. Without knowing how a data breach will disrupt operations, it can be impractical to gauge the appropriate level of effort and capital to invest in precautions and countermeasures. A well-defined process and taxonomy that quantifies the impact of risks can help to align risk management practices with organizational goals. Without an integrated risk management approach to security in place, a single security risk can propagate through an organization’s assets. With more and more elements being digitized, automated, and controlled with connected technology, a data breach can even result in the disruption of physical operations. When operational resilience relies on the strength of a single measure, that one defense becomes so critical that it becomes difficult to quantify the results of that defense being compromised. A defense in depth, integrated risk management-based security strategy allows for atomized risk appraisals of any given practice or process. The growing necessity of defense in depth security practices places a new responsibility on the risk management landscape. While the integrity of a single perimeter defense system can be determined with existing industry practices, the sheer density of security measures calls for new processes to monitor and control an organization’s risk management practices. The pandemic revealed previously ignored or unaddressed weaknesses in many organizations. Our 2020 Digital Risk survey found that nearly 75% of respondents expect their digital initiatives to accelerate due to the disruptions and shifts over the past year. While some of this acceleration will include expansion of existing approaches and practices, new processes to meet the expanding risk profile can help an organization match the shifting environment. Operational risk programs should bring risk information together so you can better understand your risk posture, determine more easily how to treat risks, as well as see the interrelationship of these risks to the entire business. Integrated Risk Management Moving Forward Comprehensive approaches to operational resilience require detailed audits of weaknesses in every part of a risk management strategy. Most of our customers expect their risk profile to expand significantly in the next two years. We work with organizations to manage their expanding risk profile on our powerful integrated risk management platform. To discover how the organizations that utilize a mesh security approach are outcompeting even in times of disruption, read our whitepaper, “The State of Integrated Risk Management.”  https://www.bloomberg.com/news/articles/2021-06-04/hackers-breached-colonial-pipeline-using-compromised-password
- How to Leverage Compliance Towards Operational Resilience
Compliance is often a logical, externally driven starting point for risk management programs. Staying ahead of changing regulations can be a daunting task. Factor in disruptions like the pandemic and the evolving business landscape and it becomes clear that no single risk management function standing alone can adequately protect an organization from risk. Rather, companies need an integrated risk management approach focused on operational resilience to adapt and prosper in times of upheaval and increased potential risk. With integrated risk management, companies go beyond compliance to layer on audit management, enterprise and operational risk management, third-party governance, and other functions. This layered, “mesh” approach creates a more holistic model providing depth to the risk management strategy. In our whitepaper, “The State of Integrated Risk Management”, we outline the lessons learned by those who thrived in their digital transformation efforts during the pandemic to help companies along their journey to improving business outcomes through operational resiliency. Get the insights and read more about the four themes of operational resiliency here. Compliance is Still Foundational but Not the Endgame Many times, individual departments may create their own compliance processes to address policies and meet regulatory obligations. This siloed approach makes it difficult to identify, prioritize and respond to issues that impact your business. With changing priorities and resources stretching due to shifting business needs, disconnected processes not only impact an organization’s productivity but also its ability to sustain and grow the business. By establishing a coordinated and consistent compliance program, the executive team can get the full picture of the state of compliance across the entire organization. Organizations should establish formal processes for stakeholders to understand and manage changes that may affect the organization’s compliance, including how new and changing activities may impact the organization’s obligation. A coordinated approach to compliance improves operational resiliency and should create a proactive approach that supports a holistic risk management strategy. More than 1/3 of respondents in our survey stated a risk-based compliance methodology is a priority for them in the next two years illustrating the cross-over between compliance approaches and risk management. Why Operational Resilience is End Game While compliance is a critical component of managing risk, operational resilience has become an increasingly important topic. Risk today is multidimensional, and the frequency and magnitude of disruptions, like the pandemic, have motivated organizations to take a deeper look at how they identify and analyze risk and how they plan to avoid or recover from them. Operational resilience considers the strategic goals of the organization, engages all parts of the organization, and embraces integrated risk management to drive the development of resilient business practices. Strong operational resilience can: Improve the company’s finances by reducing costs that would have been incurred during a disaster. Drastically reduce operational disruptions by preparing for potential disasters before they occur. Allow you to respond swiftly in crisis situations to protect your ongoing operations. Minimize the impact on your business by breaking down the silos across functions and teams. Help organizations have the capacity to quickly put together mergers and acquisitions Help organizations swiftly adapt to changes in technology due to digital transformations. Improve visibility over all the performances of different sectors paramount to the organization’s growth and the resources necessary to achieve the goals. Provide complete oversight over all the company’s outsourced operations. How to Create a Culture of Operational Resilience The ability to absorb changes and adapt to an evolving risk environment is a regulatory, corporate, and board-level topic within many organizations. Traditionally, building a culture of resiliency is a function of an effective business continuity management program. To build ownership across the entire organization, each department from IT to sales must proactively participate in implementing operational resilience into processes, systems, and practices. This cultural change should be led at the executive level. Gartner predicts that by 2025, “70% of CEOs will mandate a culture of operational resiliency to survive coinciding threats from COVID-19, cybercrime, severe weather events, civil unrest, and political instabilities.”(1) Having change driven by the chief operating officer (COO) or chief information officer (CIO) helps to reinforce the importance of implementation. The first thing organizations should do when creating a culture of resiliency is have a definite purpose and aim. When organizations have a clear vision that every sector can relate to, it is easier to work together and achieve mutually beneficial goals. Second, organizations must establish consistent procedures and policies. For a program to thrive, all departments and functions performing separate risk management activities should be using the same methodologies, tolerances, and toolsets. Last, it is vital that internal and third-party organizations are as aligned in their resiliency efforts as they are in their delivery of products and systems. This alignment can be accomplished in the onboarding process, service-level agreements, or clauses in contracts. The State of Integrated Risk Management: Themes of Operational Resilience Strong compliance processes are one step, albeit a critical foundational step, towards achieving operational resilience. Programs focused on operational resiliency bring risk information together so you can better understand your risk posture, determine more easily how to treat risks, as well as see the interrelationship of these risks to the entire business. Explore the other themes of operational resilience by downloading our whitepaper, “The State of Integrated Risk Management”. Archer Solutions As a leader in providing integrated risk management solutions, we can help you with strategic-decision making and improving your operational resilience. Contact us today to see how Archer Regulatory and Corporate Compliance Management can aid you in providing a clear consolidated view of your organization’s state of compliance and how an integrated risk management approach better prepares you to thrive in a multidimensional and evolving risk landscape. (1) Gartner: Predicts 2021: Operational resiliency. January 2021.
- Why is Integrated Risk Management Critical to Business Growth and Continuity?
As your organization evolves, so too does your risk landscape. Risk is inherent in all types of initiatives within business operations such as the expansion of digital processes can increase security risk and outsourcing business operations to third-party vendors creates complexities in your supply chain. For any organization to thrive in these transformative times, it must have a solid risk management strategy. The growing recognition that all risk is connected has led to companies realizing that they need coordination across all risk functions – including leveraging the same data, platform, taxonomy, and output. This coordinated strategy is called an integrated risk management approach. Integrated risk management gives organizations the ability to navigate risks and deal with them effectively (should they arise) without hindrance in business operations. An integrated risk management approach gives senior management and executives actionable and detailed data so that they decide on an action plan that is best for the organization ultimately improving overall performance. The pandemic put a spotlight on the need for companies to have an integrated risk management approach with emphasis on operational resilience, or a company’s ability to absorb and adapt to sudden disruptions and continue to meet business goals. We recently analyzed the Archer customer base to discover how our customers not only survived but thrived during this global upheaval. What we found fundamentally accentuated the need for integrated risk management strategies. When respondents to the RSA 2020 Digital Risk Survey were asked about the need to coordinate risk management, the “extremely coordinated” response jumped more than 90% in the short time between the question being asked in a 2019 survey and the 2020 survey. The key learnings and the four integral themes of integrated risk management are outlined in our new whitepaper, “The State of Integrated Risk Management”. Digital Transformation, the Pandemic and Major Forces on Risk Change is constant, but the alarming rate at which the world is digitally transforming has major impacts on existing business models and operations. Almost 55% of respondents in the 2020 RSA Digital Risk survey stated their organizations were extensively engaged in digital transformation initiatives highlighting the pervasive use of technology to advance business operations. The pace of digital efforts were accelerated in light of the pandemic, forcing organizations to find alternative, technology enabled methods to support their workforce and deliver products and services to customers. As Gartner found, “The momentum of digital transformation projects is outpacing the ability of organizations to accommodate the changes and will introduce additional complexity of threats.” (1) This rapid digital transformation also makes organizations more vulnerable to cyber-attacks and virtual disruption. A more fluid risk landscape has emerged requiring a more holistic and integrated approach to risk management. The pressure to manage risk is evident with over 60% of respondents in the 2020 RSA Digital Risk survey stating their companies' integrated risk management programs were somewhat or quite extensive. Obviously, integrated risk management approaches have become the norm – not the exception. How did COVID Affect Risk Management? The COVID 19 pandemic had a severe negative impact on organizations all around the globe. COVID brought about major changes in the technological, social, economic, and political aspects of the world. These changes have made organizations pay more attention to overseeing, anticipating, and mitigating threats caused by unfavorable interruptions to business operations. A PwC study found that respondents that shifted risk management responsibilities to the first line were more likely to show profit and revenue growth over the next two years and were able to recover from adverse events more quickly. (2) While the pandemic affected multiple areas of risk, two areas of risk highlight the coordination needed to address today’s risk environment. Cyber Attacks The pandemic forced many companies to go remote and conduct business virtually. Opportunistic cyber breaches increased in 2020 and adopted technologies put more undue pressure on business and IT resource availability making it more important than ever to have solid and effective recovery plans. Often, IT disaster recovery teams are on a different page than business continuity teams of what’s critical to protect and recover, highlighting the need for an integrated approach and improving cyber resiliency. Additionally, remote working promotes fraudulent activities like phishing. The cybercrime economy thrives in times of chaos, with unchecked growth in fraud attempts and other risks. 79% of respondents in the RSA 2020 Digital Risk Survey expect to rely more heavily on the IT and security risk management portions of their risk programs over the next two years. Compliance This remote working environment then made it even more difficult to enforce compliant behavior among staff. In addition, regulators saw how the pandemic affected different industries and have begun addressing some of the gaps they have observed through new regulations. The result is a more complex regulatory environment with a challenging enforcement playing field. In response, risk-based approaches are necessary to identify the most impactful compliance requirements. This played out in the RSA Digital Risk Survey with more than 1/3 of respondents in the survey stating a risk-based compliance methodology is a priority for them in the next two years. In addition, the technology operations have a tremendous impact on the compliance strategy. Therefore, the overlap in compliance and IT and security risk management is obvious. A coordinated strategy, via Integrated risk management, needs to focus on compliance measures that are suitable for the present working environment. The convergence of compliance and IT and security risk management is evident within the Archer customer base. Of the 1100+ deployments Archer has for IT and security risk management, more than 80% utilize compliance processes on the Archer platform. How to Achieve Resilience Through Integrated Risk Management One thing is certain, the pandemic has highlighted the need for resilience, especially as other high-magnitude disruptions continue to mount. Achieving resiliency, however, is another matter – it requires forethought, discipline, and constant vigilance. These five steps are key to building resiliency: Develop and adopt a holistic enterprise-wide integrated risk management system and governance. Develop a risk profile, assess your risk landscape, and a strategy for operational resilience. implement change initiatives that are focused on proactive instead of reactive. Lead from the top to maintain and adopt management protocols that ensure the company's growth. Ensure compliance via enforcement of organization standards, policies, and regulations across all sectors of the organization. The State of Integrated Risk Management While many companies were caught off guard by the pandemic, a lucky few were able to quickly pivot and thrive in their ongoing business operations and digital transformation efforts. Our whitepaper, “The State of Integrated Risk Management”, outlines key themes related to operational resiliency and integrated risk management and the underlying success factors of those who were able to take advantage of extraordinary opportunities presented. Download the paper now, and contact us today and begin your journey to operational resilience. (1) Gartner: Predicts 2021: Operational resiliency. January 2021. (2) PricewaterhouseCoopers. Risk in Review: Managing Risk from the Front Line Correlates to Higher Revenue and Profit Growth, Says PwC. 2017. https://www.pwc.com/us/en/press-releases/2017/risk-in-review-managing-risk-from-the-front-line.html
- Archer Continues to Lead the Way
Leadership takes many forms. We recently celebrated our 20th Anniversary at the Archer Summit 2021 in Orlando, marking a long history of leadership in the GRC and Integrated Risk Management space. That same week, Gartner published the second of its two current Risk Management focused Magic Quadrants for the year (IT Risk Management and IT Vendor Risk Management Tools) both of which once again recognized Archer as a “Leader.” Both reports mark the 6th consecutive time we’ve been a Leader, and in total their publication marks 24 consecutive times Archer has been a Leader in any of the Magic Quadrants focused on Risk Management. This is obviously an outcome we’re very proud of as a team, and I think reflects on our continued commitment to execution and vision. But as I said, leadership takes many forms. And personally, I’m equally proud of many of the areas we’ve executed against a vision in the past year, many of which were not part of the evaluation criteria for Gartner, but were a primary focus at Archer Summit. Advancing the discussion around quantitative risk analysis beyond Cyber Risk is leadership. We all understand the importance of IT risks (including but not limited to cyber security). And maintaining leadership in these areas is of course an important part of delivering true Integrated Risk Management. But it’s not the only area of risk that organizations need to manage carefully. This is why we launched Archer Insight earlier this year, making us the first of the true IRM providers to extent risk quantification, bowtie and other critical tools for analysis across the full range of risk drivers. Innovating the industry’s leading risk management platform to support broader stakeholder engagement is leadership. One of Archer’s core capabilities that customer praise the most is how the platform supports very deep dives for the core risk manager/risk administrator persona. But we also see how risk, as it expands into new areas of the business, really requires the participation of a wide range of users, including many who will have much less frequent interaction with the platform. Our development of Archer Engage is aimed directly at supporting risk management teams in their efforts to help first line operators, vendors and other stakeholders participate in risk efficiently and effectively. Extending core business continuity and IT risk programs into true Operational Resiliency is leadership. The need for organizations to extend beyond what has all to often been a siloed focus on IT business continuity/disaster recovery is not new. But last year’s pandemic and the shock to the system that caused across all aspects of operations has accelerated for many the need to better prepare of disruptive scenarios. And that disruption isn’t limited to IT delivery and in fact needs to be driven by a broad and prioritized view of how these scenarios that could impact the ability to provide products and services. This is exactly where we’ve gone with the recent launch of Archer Operational Resiliency, combining current regulatory guidance and best practices as a foundation for building operational resilience. Supporting our customers in pursuit of new Board-level strategic imperatives is leadership. From the beginning, risk management was meant to focus on the most critical strategic areas of a business. Continuous waves of regulation drove some to turn focus towards regulatory compliance and audit capabilities, also a core tenant of Integrated Risk Management. But we see Boards and CEO’s increasingly expecting their Risk Management functions to focus more fully on awareness, assessment and response to those risks that threaten overall corporate valuation. Few business trends have taken Board-level discussion by storm the way ESG (Environmental, Social & Governance) has over the past year. This drove the very recent launch of Archer ESG, which we see as an incredibly natural extension of how customers leverage our platform today, providing improved ability to gather, assess and align ESG data with internal plans and external regulations. And most importantly, help organizations gain early visibility into the risks that threaten ESG success. A thanks to the entire Archer Community for all that they’ve done and continue to do to drive us to lead. Many of you have spurred the development that supports our Leadership recognition by Gartner. More still have acted as catalysts in these recent areas of innovation. And finally, a thank you to those from the Archer Community that were able to join us at this year’s Archer Summit, in person or virtually. We look forward to the next year of news and developments from Archer, and sharing those with all of you.
- What is Operational Resilience?
The world as we know it is dynamic, and the global pandemic has emphasized the fragility of human and organizational operations in the connected world of today. Companies are not only trying to recover from the drastic changes of the pandemic, such as remote work, but from the impact of the shifting risk landscape and how it has affected their business goals and outcomes. With an eye on the importance of riding the waves of disruptions and change we see today, organizations need to achieve operational resilience to survive. Operational resilience is the ability of an organization to absorb and adapt from any threat or unplanned disruption. It is a coordinated, consistent, and automated approach to business continuity that goes beyond recovery of internal processes to focus on external services and product delivery. Operational resilience includes traditional elements of IT disaster recovery, planning, testing, and execution, that allows for a swift response during crises to protect an organization’s ongoing operations but takes steps closer to the overall business objectives and strategies. An organization that takes time to construct a solid risk management strategy will thrive in this age where business risk is increasingly connected. Therefore, integrated risk management is the foundation for operational resilience. An organization that has achieved operational resilience will continue to function properly and achieve its goals even amidst interruptions. While the burden of resiliency is one that every employee should carry, senior management should focus on assessing and understanding the risk levels of the organization and its readiness for disasters and unexpected scenarios. Gartner predicts that by 2025, “70% of CEOs will mandate a culture of operational resiliency to survive coinciding threats from COVID-19, cybercrime, severe weather events, civil unrest, and political instabilities.”i Our whitepaper, “The State of Integrated Risk Management” discusses the importance of resiliency starting top-down from leadership. Communicating Operational Resilience in Your Organization To effectively and optimally manage risks, organizations must adopt a holistic approach to overseeing every aspect of the multiple risk management functions. Usually, organizations carry out risk management in silos; each department deals with its own risk management and possible disruptive scenarios. Occasionally effective, this method is not ideal for companies that seek to thrive in the long run, especially in their digital transformation efforts. The silo method does not take into account the risk assessment of the company as a whole. Any risk assessment done in any sector is only as effective as that sector deems fit. Uncoordinated, ad hoc processes can leave a business vulnerable and recovery plans ineffective. Operational resilience deals with assessing and understanding the risk tolerance levels in every sector - to proactively manage risks throughout the organization. Resilient organizations look at both internal and external risks as they understand that risk can also originate from third parties. They have risk management plans in place for any disruption, whether cyberattack, natural disaster, or global pandemic. Companies with operational resilience also must consider risks beyond their own four walls. They know that good communication is imperative to coordination. When a disruption or threat arises, senior managers must convey information to every party involved, including disaster recovery and crisis teams and, if necessary, consumers. Internal and external communications are incredibly important in risk management to reduce impact and maintain business continuity. An organizations’ resilience can be improved by ensuring visibility and communication with the following: Clients Stakeholders Distributors Vendors Suppliers Partners And every other set of persons that can have an impact on the organization. Interdepartmental communication is crucial to the success of shifting from a reactive to a proactive risk management structure. Operational resilience is a cultural mindset change that drives the implementation of resilient practices throughout the business. How to Embed Operational Resilience in an Organization There are some integral steps that organizations must adopt to transform from recovery to operational resilience. Adopt a Holistic Perspective to Viewing Organizational Risks Organizations should consider both internal and external factors that can have a direct or indirect impact on the organization. Take into consideration the people, technology, programs, and processes, etc. associated with the business. An effective enterprise risk analysis must consider risks across every sector and division of the organization. This strategy enables employees and teams to come together to envision potential disruption scenarios that may arise. Design a Comprehensive Risk Assessment System. To manage risks, organizations must be able to access and predict possible risks scenarios. This is where communication plays a major role, as everyone in the organization must be informed about evolving business priorities that inform recovery and response processes. When members of the organization are on the same page, potential threats and interruptions can be properly analyzed, understood, and documented. Consider the upstream and downstream dependencies, systems, and processes, and how your team plans for them. Identify Possible Failures in Existing Processes and Remedy Them While every failure that may arise from existing processes may not need to be documented, it is critical to identify key scenarios and focus on the capabilities that prepare for those specific scenarios AND related, derivative, or similar situations. Assess different threats levels and types to proactively plan against them. An effective program must include a cycle for learning and improving processes, so it’s important to bring the continuity and recovery professionals managing day-to-day incidents or planning and testing for crisis events together, Operational Resilience and The State of Integrated Risk Management We want companies like you to benefit from the risk management lessons learned by our customers during the height of the global pandemic. In our State of Integrated Risk Management report, we outline the key discoveries and insights garnered from those who thrived despite the worldwide upheaval. Get the whitepaper now to read more about the four themes affecting organizations today, and how your business can benefit from an integrated risk management strategy focused on resiliency. Archer’s Business Resiliency Solution At Archer, we can help you scale through uncertainties and digitally transform your business to the next level through strategic decision-making. Contact us today to discover how to improve your organization’s operational resilience to make your company better suited to handle risks, improve business outcomes, and ease your digital transformation process, especially during times of disruption. i Gartner: Predicts 2021: Operational resiliency. January 2021.
- Operational Resilience is Necessary to Thrive Amid Disruption
The world is fast becoming a more turbulent place and disruptive events are occurring more frequently and they are less predictable as the following McKinsey study shows. The recent public health crisis, coupled with a consistent increase in cyber-attacks, natural disasters, geopolitical conflicts and a myriad of other events are causing organizations to reflect on the need to evolve from just being recoverable to becoming resilient – which is the ability to absorb disruption and not only continue to deliver on strategic objectives, but to quickly adapt and prosper. Surviving disruption is not the only reason to build a resilient organization – operational resilience is a required trait in business today. Competition is fierce, shareholders require consistently strong returns, the public and many investment funds demand that organizations be socially conscious and actively engaged in contributing to the greater good. As a result, organizations can’t afford to operate in a reactive mode – these demands require that organizations be resilient. Resilience is good business practice as illustrated by a McKinsey study performed after the 2007 financial crisis which showed that resilient organizations emerged from the crisis more quickly and stronger and not only out-performed non-resilient organizations, but the S&P 500 index well after the recovery period. A Harvard Business School study broke resilience down into attributes that include being adaptable, prioritized, data-driven, aligned and continuously improving. These attributes contribute to being a well-performing organization. Building a resilient organization focuses on what the organization does to provide products and services to its end customers, and the interdependencies. Organizations quickly learn that building resilience across an intricate, interconnected organization with many interdependencies is complex and expensive. A challenge is not creating more cost as you build resilience but developing an approach that provides a return on investment on your efforts over the short to medium term. In this respect, building resilience must be somewhat self-sustaining. Risk management is also an integral part of building a resilient organization because as new risks emerge, the organization must be prepared to identify, assess, treat and monitor them and their effects on the organization. Turning the strategic objective of building a resilient organization into real results can be a challenge. It takes executive focus, a programmatic approach that aligns risk, resiliency, compliance, and third-party management teams, and drives active participation across the organization. The underpinnings include prioritization, planning, coordination, engagement, and constant improvement to drive the actions that will result in building a resilient organization. Learn about how Archer Operational Resilience solution can help you build a resilient organization.
- Archer State of Integrated Risk Management Report
Whether you call it Integrated risk management or Governance, Risk and Compliance or just plain old organizational common sense, the idea to manage risk within today’s competitive and constantly changing environment is an absolute necessity. In the past year, technology shifts, market disruptions and unique obstacles have made keeping tabs on the barriers to strategic business goals a constant battle. Piling on top of the usual suspects of security, operational risk, and regulatory compliance are the topics of operational resilience, third party risk and Environmental, Social and Governance (ESG) risk. While those themes have been part of the risk landscape for years, they seem to have matured from precocious toddlers to full blown adolescence – wreaking havoc - overnight. At this juncture, we felt it was important to take a step back and look at the risk management industry. The Archer State of Integrated Risk Management report is based on several inputs. We analyzed our customer base to identify trends and indicators. With over 1500 deployments, Archer is used by companies of all sizes, in all industries and across the globe. Additionally, we have customers that have deployments of over 15 years. This coverage gives us unique insights into what capabilities companies target as they mature their risk management programs. We also analyzed specific results from the 2020 RSA Digital Risk Survey relevant to integrated risk management priorities. This survey consisted of targeted questions regarding risk priorities today with responses from 1,100 risk, security and business professionals. Based on our own experiences working with our customers and these inputs, we identified four industry themes that provide a perspective on integrated risk management. Compliance is still foundational, but operational resilience is the end game. Convergence of digital and traditional business means organizations must not stop at IT and security risk management or disaster recovery. Quantification based on well-established mathematical principles is the best way to calculate risk—and it’s easier than ever. Risk management maturity over time is complex yet achievable. We also noted how risk management technology has evolved in the face of change. Over the last 20 years, Archer has evolved from organizing catalogs of key elements of the risk management program into the enterprise business support tool with workflow, reporting and decision support that enables integrated risk management and bring significant ROI. 2020 brought tremendous disruption to organizations but also offered an extreme example on what it takes to be resilient. Disruption doesn’t play favorites – but those organizations prepared for it can not only survive but thrive. Operational resilience takes forethought, discipline and constant vigilance. Integrated risk management plays a critical role in developing these capabilities. Risk management is both a proactive and reflective process taking not only experience and expertise to learn from the past, but also commitment and focus to innovate for the future. Download the report to learn more about the state of integrated risk management and see how your organization stacks up towards building the resilience it needs in today’s risk landscape.
- Drive Better Risk-Based Decision Making with Enhanced Heat Mapping in Archer Insight
Today we are excited to introduce Archer Insight, a set of quantitative risk analysis capabilities which, when paired with Archer’s industry-leading integrated risk management platform, supports improved risk-based decision making. Archer Insight features a wide range of enhanced risk analysis capabilities; this blog focuses on one feature we expect to be of high interest to risk analysts, specifically improved risk heat maps. Risk heat maps are a basic communication tool for the risk manager, providing a visual overview of the portfolio of identified risks. On one axis is the likelihood of the risk occurring, and on the other axis a measure of the impact should the risk occur. Those risks with the highest likelihood and impact are most threatening and the corresponding quadrant is colored red. Those risks with the lowest likelihood and impact plot in the quadrant colored green to reflect their relative unimportance, and the area in between is typically colored yellow or orange. Traditional heat map Despite its ubiquitous popularity, the traditional risk heat map presents several challenges: Clearly not all squares of the same color represent risks of the same severity, but the qualitative evaluation of likelihood and impact magnitude do not allow a rational method for defining finer gradations along the red-to-green spectrum. Likelihood is typically equated to probability of occurrence for events that can occur at most one time (like the destruction of a building or the loss of a dataset to the Dark Web) or frequency of occurrence for events that can occur multiple time (like fatal accidents, system shutdowns or regulatory fines). The former scales from 0 to 1, while the latter can take any non-negative value. It is therefore very challenging to show both types of likelihood on the same plot. For example, if an expected frequency of five times a year is ‘High’, then to be consistent a probability of 100% would be lower, which does not make intuitive sense. Representing low likelihood risks is also challenging. One might say that a risk with a 10% chance of occurrence should fall into a ‘Low’ category, but this is still quite significant – if you have 10 such risks, it is almost certain that one of them would occur. On the other hand, a risk with a one in a thousand chance of occurring would fall into the same ‘Low’ likelihood category. When an impact can take a wide range of values, it is extremely challenging to decide how to present the risk. For example, a factory accident might have a 10% chance of occurring in a year, but its impact could be anything from some minor bruises if lucky (Low), most probably an outpatient visit by a worker (Medium Low), but in the most extreme circumstances there could be several fatalities (High). If the risk is evaluated as [Likelihood,Impact] = [Low,Medium Low], there is no recognition of the very severe possible outcome, but if it is represented as [Low,High], the evaluation is exaggerated. A new vision for heat maps Archer Insight introduces quantitative estimation of risks through simple, intuitive evaluation techniques that require no expertise on probability modeling or math. It resolves the probability/frequency dilemma, and it allows users to express the range of possible resultant impacts if needed. Archer Insight also introduces quantitative bowtie methods to express how one risk may have more than one consequence. For example, a car crash (risk event) could result in several consequences – from being late for work to repair bills to injuries and fatalities to the passengers and larger public: Bowtie analysis for a car crash These consequences produce impacts of different dimensions: money for repairs, time for delays, and level of injuries/fatalities for people. It is even possible to map several risks to the same consequence. For example, several different risks might all lead to the cancellation of a contract (the consequence) with an important financial impact. Archer Insight automatically calculates the aggregate likelihood of the consequence occurring, taking into account all the different ways it could happen. The option to include a richer description of risk has made it possible to rethink the heat map, and produce new visualization that is more precise, comprehensive, and useful for decision makers. The standard Archer Insight heat map has an impact scale that ranges from ‘Extremely Low’ to ‘Catastrophic’ plus a ‘Nil’ category so that one can represent when the impact of a consequence has been avoided completely. The finer gradation, together with guiding definitions, allows a far more precise evaluation of impact. Moreover, Archer Insight allows you to specify ranges of impacts, both qualitative and quantitative. Its sophisticated algorithm translates these inputs into a consistent scaling system, even across different impact types. The algorithm ensures that all consequences plotting in the same color are equivalent in importance. Archer Insight P-I table for consequences with heat map overlay The vertical axis is numeric, accommodating both probability and frequency, which is automatically adjusted to reflect the business time horizon and any changes in the window of opportunity for the risks to occur. Pre-and post-risk treatment evaluations are shown together using “tadpole tails”: Tadpole tails – the head represents the current status, the end of the tail represents the evaluation prior to any risk treatment This allows the manager to appreciate the level of reliance on the effectiveness of risk management strategies. If the line is long, the reliance is large. The heat map allows you to drill down by selecting a specific entity and a specific type of impact if required. Hovering over a consequence will show a description popup, clicking on the dot will highlight the consequence in the accompanying table, and clicking the table entry will show a wealth of information describing the strategy being used to manage the consequence: Archer Insight P-I table filtered for Reputation consequences with heat map overlay One can also view risk events instead of consequences. Archer Insight then displays each risk event, accounting for the multitude of consequences that might arise from it: Archer Insight P-I table for risk events with heat map overlay switched off To learn more about how Archer Insight is enabling an enhanced level of risk-based decision making, register today to attend our August 4 webinar, where we will explore these improved heat maps and many other features of Archer Insight.